India’s IT Ministry Reviews WhatsApp Response on Username Feature Amid Growing Cybersecurity Concerns

indias-it-ministry-reviews-whatsapp-response-on-username-feature-amid-growing-cybersecurity-concerns

NEW DELHI — In a major regulatory development at the intersection of consumer privacy and national security, Meta-owned instant messaging giant WhatsApp has submitted its formal written response to the Union Ministry of Electronics and Information Technology (MeitY) regarding its controversial proposed "username" feature.

According to senior government officials, the written submission was delivered late Thursday evening on July 9, 2026. The ministry has confirmed that it is actively reviewing the tech giant’s response as of Friday, July 10, 2026, to determine whether the platform’s proposed privacy measures align with India’s stringent cybersecurity guidelines and intermediary liability rules.

The dispute highlights an ongoing global debate: the delicate balance between safeguarding user privacy through data minimization and ensuring that law enforcement agencies possess the necessary tools to track and combat rapidly evolving online fraud networks.


Main Facts of the Dispute

The core of the disagreement lies in WhatsApp’s development of a "username" feature. Traditionally, WhatsApp accounts have been tied directly to verified mobile phone numbers, meaning any interaction on the platform requires the disclosure of a user’s phone number. The proposed feature would allow users to create unique, custom usernames (e.g., @username), enabling them to communicate with others without revealing their personal phone numbers.

While privacy advocates have welcomed the feature as a crucial step toward protecting users from unwanted spam, stalking, and data harvesting, the Indian government has raised serious red flags. On July 1, 2026, MeitY issued an official notice directing Meta to immediately halt the rollout of this feature in the Indian market.

The government’s primary objections center on security and accountability. MeitY argues that allowing users to conceal their phone numbers behind custom usernames would:

  • Facilitate Anonymity for Bad Actors: An anonymous layer could make it significantly easier for cybercriminals to operate with impunity.
  • Exacerbate Online Fraud: The government fears a sharp rise in phishing campaigns, financial scams, and credential harvesting.
  • Fuel "Digital Arrest" Scams: India has seen a surge in sophisticated "digital arrest" scams, where fraudsters impersonate law enforcement, customs officials, or federal agents over video calls to extort money. Anonymized profiles could make these impersonation tactics harder to trace.
  • Hinder Law Enforcement Investigations: Obfuscating the primary identifier (the phone number) complicates the process of gathering actionable intelligence during criminal investigations.

Chronology of Events

The regulatory standoff has unfolded rapidly over the first ten days of July 2026:

Govt. receives WhatsApp’s reply on notice over ‘username’ feature
[July 1, 2026]  --> MeitY issues formal notice to Meta to halt the WhatsApp username rollout.
[July 4, 2026]  --> Original deadline for WhatsApp's response; platform requests extension.
[July 9, 2026]  --> IT Secretary S. Krishnan addresses notices sent to other platforms (Telegram, Signal).
[July 9, 2026]  --> WhatsApp submits its comprehensive written response to MeitY in the evening.
[July 10, 2026] --> MeitY confirms receipt and begins formal review of WhatsApp's submissions.

The Initial Directive

On July 1, 2026, the central government sent an urgent directive to Meta. The communication explicitly instructed the company not to launch the username feature until comprehensive consultations were completed "to the satisfaction of the Government." The ministry set an initial deadline of July 4, 2026, for WhatsApp to submit its legal and technical justifications.

The Extension and Assurance

Recognizing the complexity of the policy implications, WhatsApp formally requested an extension of the July 4 deadline. Along with this request, the platform provided a firm assurance to MeitY that it would suspend any plans to deploy or test the username feature within the Indian jurisdiction while bilateral discussions remained ongoing.

Broadening the Regulatory Net

On July 9, 2026, Union IT Secretary S. Krishnan revealed that the government’s scrutiny was not limited to Meta. MeitY dispatched similar inquiries and notices to other prominent messaging applications operating in India, including Telegram, Signal, and the Zoho-developed domestic app Arattai. Unlike WhatsApp, these platforms have permitted username-based communication and phone number concealment for several years.

Addressing the media, Secretary Krishnan noted, "There is still a little more time, so the replies [from Telegram and Signal] have not yet been received… we will examine this issue holistically once all responses are in."

Submission and Review

Late in the evening on July 9, 2026, WhatsApp delivered its detailed written response to MeitY. By the morning of July 10, 2026, senior ministry officials confirmed that the document had been received and was undergoing a multi-departmental evaluation.


Supporting Data and Context

To understand the scale of this regulatory intervention, it is necessary to examine the sheer volume of WhatsApp’s operations in India, alongside the legal framework governing digital platforms.

WhatsApp’s Footprint in India

India is indisputably WhatsApp’s largest global market.

Govt. receives WhatsApp’s reply on notice over ‘username’ feature
Metric Details
Estimated Indian User Base Over 80 crore (800 million) active users
Statutory SSMI Threshold 50 lakh (5 million) registered users
Regulatory Status Significant Social Media Intermediary (SSMI)
Governing Legislation Section 2(1)(w) of the IT Act, 2000 & IT Rules, 2021

Because WhatsApp’s user base of 80 crore vastly exceeds the statutory threshold of 50 lakh, the platform is legally classified as a Significant Social Media Intermediary (SSMI). Under the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, SSMIs are subject to heightened due-diligence requirements, proactive monitoring obligations, and a mandate to assist government agencies in identifying the "first originator" of malicious information under specific legal circumstances.

The Rise of Cyber Fraud in India

MeitY’s aggressive stance against username anonymity is fueled by an unprecedented spike in cybercrime across the country. According to data from the National Cyber Crime Reporting Portal (I4C), financial frauds, identity thefts, and impersonation scams have transitioned heavily to encrypted messaging apps.

"Digital arrest" scams have emerged as a particularly lucrative tool for international syndicate networks. Scammers use WhatsApp’s voice and video call features to display fake police backdrops, presenting forged arrest warrants to terrorize victims into transferring their life savings into mule bank accounts. The government fears that if these accounts can be set up under untraceable usernames without a publicly visible phone number, the success rate of such scams will surge while the detection rate will plummet.


Official Responses and Legal Arguments

The Government’s Position

MeitY’s legal argument rests on the premise that WhatsApp, as an SSMI, must prioritize public safety and national security over unilateral product changes. The ministry asserts that Section 2(1)(w) of the IT Act, 2000, read alongside the IT Rules of 2021, gives the state the authority to intervene when a platform’s design choices threaten to weaken law enforcement’s investigative capabilities.

A senior IT Ministry official, speaking on the condition of anonymity, stated:

"While we support user privacy, we cannot allow features that dismantle basic accountability. When a victim is defrauded on a messaging app, the first point of investigation is the phone number. Removing this visible identifier hands a massive shield of anonymity to cybercriminals operating from both within and outside our borders."

WhatsApp’s Defense

While the exact contents of WhatsApp’s July 9 written submission remain confidential, industry insiders suggest that Meta’s legal and technical teams are focusing on three primary arguments:

Govt. receives WhatsApp’s reply on notice over ‘username’ feature
  1. User Safety and Privacy: Phone numbers are highly sensitive personal identifiers. Allowing usernames protects vulnerable groups—such as women, activists, and journalists—from harassment, stalking, and unsolicited communications by keeping their phone numbers private.
  2. Parity with Competitors: Platforms like Telegram and Signal have operated with username features in India for years without facing outright bans on those features. Meta argues for a level regulatory playing field.
  3. Backend Traceability: WhatsApp is expected to emphasize that even if phone numbers are hidden from public view within the app interface, they remain linked to the account on the backend. Consequently, WhatsApp can still provide verified phone numbers and registration metadata to law enforcement agencies in response to valid legal warrants and court orders.

Implications for Privacy, Regulation, and Tech Companies

The outcome of this standoff will set a major precedent for the global tech sector and the future of digital privacy in India.

The Legality of Product Vetoes

A critical legal question emerging from this conflict is whether the Indian government possesses the statutory authority to veto specific, privately engineered app features. While the IT Rules of 2021 mandate due diligence and cooperation with law enforcement, they do not explicitly grant the state the power to dictate the user interface (UI) or feature roadmap of private software applications. If MeitY attempts to permanently block the username feature, it could trigger a landmark constitutional challenge regarding corporate free speech, product design autonomy, and the right to privacy under Article 21 of the Indian Constitution.

The Privacy vs. Traceability Dilemma

This dispute reignites the long-standing battle over "traceability" in end-to-end encrypted messaging. Since 2021, WhatsApp and the Indian government have been locked in a legal battle over Rule 4(2) of the IT Rules, which requires messaging apps to identify the "first originator" of a message when ordered by a court. WhatsApp has resisted, arguing that doing so would require breaking end-to-end encryption for all users. The username dispute is an extension of this fundamental philosophical divide: the state demands complete legibility and traceability, while the platform advocates for user-centric data minimization.

Impact on Global Product Development

For multinational tech companies like Meta, managing fragmented product features across different jurisdictions is a logistical and engineering nightmare. If India permanently blocks the username feature, Meta will be forced to maintain a bifurcated codebase—one for India and another for the rest of the world. This could delay global feature rollouts and increase compliance costs.

What Lies Ahead?

The immediate next step rests with MeitY’s technical and legal experts. If the ministry finds WhatsApp’s backend traceability assurances satisfactory, it may permit a modified rollout of the username feature—potentially requiring mandatory identity verification or stricter backend reporting protocols.

However, if the government remains unsatisfied, this confrontation could pave the way for a protracted legal battle in the Delhi High Court, reshaping the boundaries of state oversight over the digital economy.